hemlockiv This doesnt preclude the possibility that the dev deliberately published safe source code then compiled malicious code
True. Reproducible builds would address this, but its more work for devs, and few seem to think its worth the effort.
Even then, it's not that difficult to obfuscate malicious code, so...
In practice, its difficult to avoid trusting the devs of the software you use.